Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Streaming media failure with Netflix, Hulu, Amazon Prime

Is there any truly feasible way for streaming media functionality to work?  I've used nearly all open source UTMs and managed Fortune 50 proxy infrastructures and the only one that consistently has complications in handling streaming media has been Astaro/Sophos.  In stating that I would like to include that other than that ongoing issue the product is wonderful and has potential.  In today's connected environments (whether is be home, small office, or small enterprise) one would expect being able to handle streaming media (even if exceptions are required) to be rather simple.


In my home alone, there are over 20 connected devices at any given time capable of streaming media.  While configuring a clientless device for one of my Roku's worked fine, this method does not scale.  I even attempted to add RegEx expressions to exclude streaming traffic specifics and this did not work as I would have expected.  As many have said the only option that truly works is MAC exclusions or disabling web filtering altogether which creates a void in the effective security controls within a UTM product.


In speaking with co-workers that have used the Astaro product for years, monitoring forums, and performing various searches, this  has been an ongoing struggle with previous versions and continues with a new product.  I'm terribly surprised this hasn't been addressed -- in fact, one would expect that the simple check box for disabling scanning for streaming media would effectively make things work.  Has anyone from Sophos really assisted in identifying and resolving the problem rather than providing bandaids or disabling security features? 



This thread was automatically locked due to age.
  • Most likely skipping netflix domains from SSL scanning helps. I use at home Netflix on iPad, Chromecast and on Computers. I've created a URL Group Netflix containing following two domains: netflix.com and nflxext.com and placed that URL Group under "Protection > Web Protection > Web Content Filter" under "HTTPS Scanning Exceptions". WOrks perfectly well for me...
  • Any chance you have an article for amazon video too? We have investigated the logs when attempting to stream, and added exceptions for the URLs observed, but it is still not working. The exceptions we have added are:

    ^([A-Za-z0-9.-]*\.)?aiv-cdn\.net\.?/
    ^([A-Za-z0-9.-]*\.)?akamaihd\.net\.?/
    ^([A-Za-z0-9.-]*\.)?amazon\.com\.?/
    ^([A-Za-z0-9.-]*\.)?cloudfront\.net\.?/
    ^([A-Za-z0-9.-]*\.)?images-amazon\.com\.?/
     
    And the video just spins with a circle and after 30 seconds comes up with an error 7017
     
    We have audio and video file catagories as well.
     
    I have checked that the 'scan audio and video files' under web>protection>malware scanning is OFF. I also have malware scan mode as realtime, and I allow unscannable content. Under web>advanced>web content caching I have the caching turned OFF as I found suggestions to do that in other articles.